Gmail and Yahoo now expect every sender to use SPF, DKIM and DMARC. Here is what each one does — in plain English — and how to check yours.
If your quotes, invoices or newsletters keep ending up in spam folders, the cause is often missing email authentication. Since 2024, Gmail and Yahoo require bulk senders to set up SPF, DKIM and DMARC, and every business benefits from them.
SPF: who may send email for your domain
SPF is a DNS record that lists the servers allowed to send email as yourdomain.com — for example your email provider and your newsletter tool. A typical record looks like v=spf1 include:_spf.google.com ~all.
- Have only one SPF record per domain.
- End it with
~allor-all, never+all. - Stay under 10 DNS lookups, or SPF checks fail.
DKIM: a digital signature on every email
DKIM adds a signature to each message that receiving servers verify with a public key in your DNS. It proves the email really came from you and was not changed on the way. Your email provider gives you the DKIM record to publish.
DMARC: what to do with fakes
DMARC tells receivers what to do with emails that fail SPF and DKIM, and sends you reports. Start with v=DMARC1; p=none; rua=mailto:you@yourdomain.com to monitor, then move to p=quarantine and finally p=reject once reports show all your real email passes.
Check your domain in seconds
Our free Email Security Checker looks up your MX, SPF, DKIM, DMARC, MTA-STS and BIMI records and explains exactly what to fix.
Need help setting it up without breaking your existing email? Talk to us — it is usually a quick job.
Need help putting this into practice?
Our team can do it for you — get a free plan and quote within 24 hours.